SSL Report: democita.klgates.com (205.149.23.205)
Assessed on:  Fri, 21 Nov 2025 21:18:40 UTC | Clear cache

Due to a recently discovered bug in Apple's code, your browser is exposed to MITM attacks. Click here for more information.

Summary
Overall Rating
T
If trust issues are ignored: B
0
20
40
60
80
100
Certificate
 
Protocol Support
 
Key Exchange
 
Cipher Strength
 

Visit our documentation page for more information, configuration guides, and books. Known issues are documented here.
This server's certificate is not trusted, see below for details.
This server does not support Forward Secrecy with the reference browsers. Grade capped to B.  MORE INFO »
This server does not support TLS 1.3.  MORE INFO »
DNS Certification Authority Authorization (CAA) Policy found for this domain.  MORE INFO »
Certificate #1: RSA 2048 bits (1.2.840.113549.1.1.10)
Server Key and Certificate #1
Subject democita.klgates.com
Fingerprint SHA256: f88dd42d810cf08a713b857496ea44becd431fc9a750061158aeb794249ae313
Pin SHA256: yq/g95MqfP5KgFkvJHgiXFDloCn0cEklS820oC75NaU=
Common names democita.klgates.com
Alternative names democita.klgates.com DemoCita.klgates.com www.democita.klgates.com
Serial Number 1b0000035664494f3a246d8bda000000000356
Valid from Mon, 03 Nov 2025 19:30:35 UTC
Valid until Sat, 05 Dec 2026 19:30:35 UTC (expires in 1 year)
Key RSA 2048 bits (e 65537)
Weak key (Debian) No
Issuer KL Gates CA Services 2019
AIA: ldap:///CN=KL%20Gates%20CA%20Services%202019,CN=AIA,CN=Public%20Key%20Services,CN=Services,CN=Configuration,DC=kldomain,DC=com?cACertificate?base?objectClass=certificationAuthority
AIA: http://crl.kldomain.com/CertEnroll/Sub01/PUSWCASUB01.kldomain.com_KL%20Gates%20CA%20Services%202019.crt
Signature algorithm 1.2.840.113549.1.1.10
Extended Validation No
Certificate Transparency No
OCSP Must Staple No
Revocation information CRL
CRL: http://crl.kldomain.com/CertEnroll/Sub01/KL%20Gates%20CA%20Services%202019.crl
Revocation status Unchecked (only trusted certificates can be checked)
DNS CAA Yes
policy host: klgates.com
issue: sectigo.com flags:0
issue: letsencrypt.org flags:0
issue: digicert.com flags:0
Trusted No   NOT TRUSTED (Why?)
Mozilla  Apple  Android  Java  Windows 


Additional Certificates (if supplied)
Certificates provided 6 (11938 bytes)
Chain issues Extra certs, Contains anchor
#2
Subject KL Gates CA Services 2019
Fingerprint SHA256: 7d487ab9d987950236baf6b7975946783ff280db85f4094eb8816ba99bd99039
Pin SHA256: PvBIL8RWjlsZ08D9ulEdN4DEzoF7WKM51gp9Yo3grwg=
Valid until Tue, 18 Jan 2033 18:22:12 UTC (expires in 7 years and 1 month)
Key RSA 4096 bits (e 65537)
Issuer KLGates2019RootCA
Signature algorithm SHA384withRSA
#3
Subject KLGates2019RootCA   Not in trust store
Fingerprint SHA256: 612be02b97f7e33436a9b77063cce15d79df540267a0990d014d6b5f58cccd23
Pin SHA256: J522uQ3hu6+HbX6v49rG31gM4CCOH8vySiZVlduKTJ0=
Valid until Sat, 13 Sep 2042 18:54:20 UTC (expires in 16 years and 9 months)
Key RSA 4096 bits (e 65537)
Issuer KLGates2019RootCA   Self-signed
Signature algorithm SHA384withRSA
#4
Subject democita.klgates.com
Fingerprint SHA256: f88dd42d810cf08a713b857496ea44becd431fc9a750061158aeb794249ae313
Pin SHA256: yq/g95MqfP5KgFkvJHgiXFDloCn0cEklS820oC75NaU=
Valid until Sat, 05 Dec 2026 19:30:35 UTC (expires in 1 year)
Key RSA 2048 bits (e 65537)
Issuer KL Gates CA Services 2019
Signature algorithm 1.2.840.113549.1.1.10
#5
Subject KL Gates CA Services 2019
Fingerprint SHA256: 7d487ab9d987950236baf6b7975946783ff280db85f4094eb8816ba99bd99039
Pin SHA256: PvBIL8RWjlsZ08D9ulEdN4DEzoF7WKM51gp9Yo3grwg=
Valid until Tue, 18 Jan 2033 18:22:12 UTC (expires in 7 years and 1 month)
Key RSA 4096 bits (e 65537)
Issuer KLGates2019RootCA
Signature algorithm SHA384withRSA
#6
Subject KLGates2019RootCA   Not in trust store
Fingerprint SHA256: 612be02b97f7e33436a9b77063cce15d79df540267a0990d014d6b5f58cccd23
Pin SHA256: J522uQ3hu6+HbX6v49rG31gM4CCOH8vySiZVlduKTJ0=
Valid until Sat, 13 Sep 2042 18:54:20 UTC (expires in 16 years and 9 months)
Key RSA 4096 bits (e 65537)
Issuer KLGates2019RootCA   Self-signed
Signature algorithm SHA384withRSA


Certification Paths
Path #1: Not trusted (path does not chain to a trusted anchor)
1 Sent by server democita.klgates.com
Fingerprint SHA256: f88dd42d810cf08a713b857496ea44becd431fc9a750061158aeb794249ae313
Pin SHA256: yq/g95MqfP5KgFkvJHgiXFDloCn0cEklS820oC75NaU=

RSA 2048 bits (e 65537) / 1.2.840.113549.1.1.10
2 Sent by server KL Gates CA Services 2019
Fingerprint SHA256: 7d487ab9d987950236baf6b7975946783ff280db85f4094eb8816ba99bd99039
Pin SHA256: PvBIL8RWjlsZ08D9ulEdN4DEzoF7WKM51gp9Yo3grwg=

RSA 4096 bits (e 65537) / SHA384withRSA
3 Sent by server
  Not in trust store
KLGates2019RootCA   Self-signed
Fingerprint SHA256: 612be02b97f7e33436a9b77063cce15d79df540267a0990d014d6b5f58cccd23
Pin SHA256: J522uQ3hu6+HbX6v49rG31gM4CCOH8vySiZVlduKTJ0=

RSA 4096 bits (e 65537) / SHA384withRSA
Path #1: Not trusted (path does not chain to a trusted anchor)
1 Sent by server democita.klgates.com
Fingerprint SHA256: f88dd42d810cf08a713b857496ea44becd431fc9a750061158aeb794249ae313
Pin SHA256: yq/g95MqfP5KgFkvJHgiXFDloCn0cEklS820oC75NaU=

RSA 2048 bits (e 65537) / 1.2.840.113549.1.1.10
2 Sent by server KL Gates CA Services 2019
Fingerprint SHA256: 7d487ab9d987950236baf6b7975946783ff280db85f4094eb8816ba99bd99039
Pin SHA256: PvBIL8RWjlsZ08D9ulEdN4DEzoF7WKM51gp9Yo3grwg=

RSA 4096 bits (e 65537) / SHA384withRSA
3 Sent by server
  Not in trust store
KLGates2019RootCA   Self-signed
Fingerprint SHA256: 612be02b97f7e33436a9b77063cce15d79df540267a0990d014d6b5f58cccd23
Pin SHA256: J522uQ3hu6+HbX6v49rG31gM4CCOH8vySiZVlduKTJ0=

RSA 4096 bits (e 65537) / SHA384withRSA
Path #1: Not trusted (path does not chain to a trusted anchor)
1 Sent by server democita.klgates.com
Fingerprint SHA256: f88dd42d810cf08a713b857496ea44becd431fc9a750061158aeb794249ae313
Pin SHA256: yq/g95MqfP5KgFkvJHgiXFDloCn0cEklS820oC75NaU=

RSA 2048 bits (e 65537) / 1.2.840.113549.1.1.10
2 Sent by server KL Gates CA Services 2019
Fingerprint SHA256: 7d487ab9d987950236baf6b7975946783ff280db85f4094eb8816ba99bd99039
Pin SHA256: PvBIL8RWjlsZ08D9ulEdN4DEzoF7WKM51gp9Yo3grwg=

RSA 4096 bits (e 65537) / SHA384withRSA
3 Sent by server
  Not in trust store
KLGates2019RootCA   Self-signed
Fingerprint SHA256: 612be02b97f7e33436a9b77063cce15d79df540267a0990d014d6b5f58cccd23
Pin SHA256: J522uQ3hu6+HbX6v49rG31gM4CCOH8vySiZVlduKTJ0=

RSA 4096 bits (e 65537) / SHA384withRSA
Path #1: Not trusted (path does not chain to a trusted anchor)
1 Sent by server democita.klgates.com
Fingerprint SHA256: f88dd42d810cf08a713b857496ea44becd431fc9a750061158aeb794249ae313
Pin SHA256: yq/g95MqfP5KgFkvJHgiXFDloCn0cEklS820oC75NaU=

RSA 2048 bits (e 65537) / 1.2.840.113549.1.1.10
2 Sent by server KL Gates CA Services 2019
Fingerprint SHA256: 7d487ab9d987950236baf6b7975946783ff280db85f4094eb8816ba99bd99039
Pin SHA256: PvBIL8RWjlsZ08D9ulEdN4DEzoF7WKM51gp9Yo3grwg=

RSA 4096 bits (e 65537) / SHA384withRSA
3 Sent by server
  Not in trust store
KLGates2019RootCA   Self-signed
Fingerprint SHA256: 612be02b97f7e33436a9b77063cce15d79df540267a0990d014d6b5f58cccd23
Pin SHA256: J522uQ3hu6+HbX6v49rG31gM4CCOH8vySiZVlduKTJ0=

RSA 4096 bits (e 65537) / SHA384withRSA
Path #1: Not trusted (path does not chain to a trusted anchor)
1 Sent by server democita.klgates.com
Fingerprint SHA256: f88dd42d810cf08a713b857496ea44becd431fc9a750061158aeb794249ae313
Pin SHA256: yq/g95MqfP5KgFkvJHgiXFDloCn0cEklS820oC75NaU=

RSA 2048 bits (e 65537) / 1.2.840.113549.1.1.10
2 Sent by server KL Gates CA Services 2019
Fingerprint SHA256: 7d487ab9d987950236baf6b7975946783ff280db85f4094eb8816ba99bd99039
Pin SHA256: PvBIL8RWjlsZ08D9ulEdN4DEzoF7WKM51gp9Yo3grwg=

RSA 4096 bits (e 65537) / SHA384withRSA
3 Sent by server
  Not in trust store
KLGates2019RootCA   Self-signed
Fingerprint SHA256: 612be02b97f7e33436a9b77063cce15d79df540267a0990d014d6b5f58cccd23
Pin SHA256: J522uQ3hu6+HbX6v49rG31gM4CCOH8vySiZVlduKTJ0=

RSA 4096 bits (e 65537) / SHA384withRSA

Click here to expand

Configuration
Protocols
TLS 1.3 No
TLS 1.2 Yes
TLS 1.1 No
TLS 1.0 No
SSL 3 No
SSL 2 No


Cipher Suites
# TLS 1.2 (suites in server-preferred order)
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030)   ECDH secp384r1 (eq. 7680 bits RSA)   FS 256
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f)   ECDH secp384r1 (eq. 7680 bits RSA)   FS 128
TLS_RSA_WITH_AES_256_GCM_SHA384 (0x9d)   WEAK 256
TLS_RSA_WITH_AES_128_GCM_SHA256 (0x9c)   WEAK 128
TLS_RSA_WITH_AES_256_CBC_SHA256 (0x3d)   WEAK 256
TLS_RSA_WITH_AES_128_CBC_SHA256 (0x3c)   WEAK 128
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xc028)   ECDH secp384r1 (eq. 7680 bits RSA)   FS   WEAK 256
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (0xc027)   ECDH secp384r1 (eq. 7680 bits RSA)   FS   WEAK 128
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014)   ECDH secp384r1 (eq. 7680 bits RSA)   FS   WEAK 256
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013)   ECDH secp384r1 (eq. 7680 bits RSA)   FS   WEAK<